ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Qualcomm Fixes 3 Zero-Days Used in Targeted Android Attacks via Adreno GPU

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-33106
+2 in the same advisory: …33107 …33063
Out-of-Range Pointer Memory Corruption in Qualcomm KGSL GPU Driver (Actively Exploited)

CVE-2023-33106 is a memory-corruption flaw (use of out-of-range pointer offset, CWE-823/CWE-119) in Qualcomm's KGSL GPU kernel driver, which manages the Adreno graphics stack. It is triggered when a local, low-privileged process submits an AUX command containing a large list of sync points through the IOCTL_KGSL_GPU_AUX_COMMAND ioctl, causing out-of-bounds memory access. A successful attacker, typically a malicious app already running on the device, can corrupt kernel memory and escalate privileges, gaining the high confidentiality, integrity and availability impact reflected in its CVSS 7.8 local-attack score. Affected products include the listed Qualcomm components (FastConnect 6200/6700/6800/6900/7800, QAM8255P/QAM8295P/QAM8650P, Flight RB5 5G Platform, AR8035, CSRA6620/CSRA6640), and the vendor's advisory describes the flaw as spanning multiple chipsets. CISA added it to the Known Exploited Vulnerabilities catalog on 2023-12-05, and public reporting indicates it was one of three Qualcomm zero-days actively exploited in targeted Android attacks alongside Adreno GPU issues; no public PoC is known.

Do: Install Android security updates or firmware from your device/OEM vendor that incorporate Qualcomm's fixes for this CVE, prioritizing devices and systems built on the listed chipsets, and check the Qualcomm security bulletin for the fixed firmware versions for each component. Because exploitation requires local code execution, avoid installing untrusted apps on unpatched devices as an interim mitigation. Organizations subject to BOD 22-01 must apply the vendor remediations per the KEV required action.

7.8<1% KEV
  • Qualcomm AR8035 firmware
  • Qualcomm CSRA6620 firmware
  • Qualcomm CSRA6640 firmware
  • +9 more
mass~hundreds of millions of devices (Qualcomm silicon across Android phones, automotive and IoT platforms); exact count unknown
CVE-2024-43047
Use-After-Free in Qualcomm FastConnect and QCA Chipset Firmware

CVE-2024-43047 is a use-after-free vulnerability (CWE-416) in the firmware of several Qualcomm connectivity chipsets and the QAM8295P automotive SoC, where maintaining memory maps of high-level operating system (HLOS) memory causes memory corruption. The flaw is scored with a local attack vector and low privileges required (CVSS 3.1: 7.8), so an attacker needs some local foothold, such as a malicious app on an Android device, and can then leverage the memory corruption for high-impact confidentiality, integrity, and availability effects, in practice a privilege escalation to system or kernel level. Anyone running devices built on the affected chips is exposed, including Android smartphones with FastConnect 6700/6800/6900/7800, devices using QCA-series Wi-Fi chips, and automotive platforms using the QAM8295P. The vulnerability is confirmed exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-10-08, and news reports describe targeted, limited Android attacks, though ransomware use is unknown and EPSS remains modest at 0.7%.

Do: Apply Qualcomm's fix through your device or system OEM: install the latest Android security updates on affected phones, and update firmware/drivers for QCA-series Wi-Fi chips and the QAM8295P automotive SoC per vendor instructions; because this is a local firmware flaw, there is no user-side mitigation short of patching. Organizations under CISA KEV must remediate per the required action (apply vendor remediations or discontinue use). Prioritize an inventory of Android devices with FastConnect 6700/6800/6900/7800 and QCA6xxx/65xxx chips, noting this flaw is being used in targeted attacks rather than mass-scale campaigns.

7.8<1% KEV
  • qualcomm fastconnect 6700 firmware
  • qualcomm fastconnect 6800 firmware
  • qualcomm fastconnect 6900 firmware
  • +9 more
massplausibly hundreds of millions of devices (affected Qualcomm FastConnect and QCA connectivity chips ship across Android smartphones, PCs with Qualcomm Wi-Fi…
CVE-2025-21479
+2 in the same advisory: …21480 …27038
Incorrect Authorization in Qualcomm GPU Firmware Across Multiple Chipsets

CVE-2025-21479 is an incorrect authorization flaw (CWE-863) in Qualcomm chipset firmware that allows unauthorized command execution in a GPU micronode, causing memory corruption when the GPU processes a specific sequence of commands. Because the CVSS vector is local (AV:L) with user interaction required, exploitation most plausibly involves a malicious local application or process driving the GPU through the vulnerable command sequence. An attacker who successfully triggers the flaw gains high-impact confidentiality, integrity, and availability effects with scope change, meaning the compromise can extend beyond the GPU component to the broader device. Affected products span Qualcomm AQT1000, FastConnect 6200/6700/6800/6900/7800, QCA6391, QCM4490, QCS4490, Snapdragon 855 (SD855), SM4635, and SM6250 firmware, i.e., chipsets used in Android smartphones and IoT/industrial devices. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-06-03, and news reports describe limited, targeted Android attacks exploiting Qualcomm GPU zero-days fixed in Google's 2025 Android security updates.

Do: Apply Qualcomm's fix by installing the Android security update from June 2025 or later (or the OEM/vendor firmware update for QCM4490, QCS4490, FastConnect, and other affected chipsets), checking your device's security patch level and chipset firmware against Qualcomm's bulletin, which lists the exact fixed versions. Organizations subject to BOD 22-01 must apply vendor mitigations per CISA's KEV required action or discontinue use of affected products; there is no known public PoC, but exploitation in targeted attacks is confirmed, so prioritize patching internet-facing and user-facing Android fleets.

8.6
group max
<1% KEV
  • Qualcomm AQT1000 firmware
  • Qualcomm FastConnect 6200 firmware
  • Qualcomm FastConnect 6700 firmware
  • +9 more
masshundreds of millions of devices (estimated)
Full article298 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananJun 02, 2025Spyware / Vulnerability

Qualcomm has shipped security updates to address three zero-day vulnerabilities that it said have been exploited in limited, targeted attacks in the wild.

The flaws in question, which were responsibly disclosed to the company by the Google Android Security team, are listed below -

  • CVE-2025-21479 and CVE-2025-21480 (CVSS score: 8.6) - Two incorrect authorization vulnerabilities in the Graphics component that could result in memory corruption due to unauthorized command execution in GPU microcode while executing a specific sequence of commands
  • CVE-2025-27038 (CVSS score: 7.5) - A use-after-free vulnerability in the Graphics component that could result in memory corruption while rendering graphics using Adreno GPU drivers in Chrome

"There are indications from Google Threat Analysis Group that CVE-2025-21479, CVE-2025-21480, CVE-2025-27038 may be under limited, targeted exploitation," Qualcomm said in an advisory.

"Patches for the issues affecting the Adreno Graphics Processing Unit (GPU) driver have been made available to OEMs in May together with a strong recommendation to deploy the update on affected devices as soon as possible."

There are currently no details on how the vulnerabilities are being exploited, in what context, and by whom. That said, similar flaws in Qualcomm chipsets (CVE-2023-33063, CVE-2023-33106, and CVE-2023-33107) have been weaponized in the past by purveyors of commercial spyware like Variston and Cy4Gate.

Last December, Amnesty International revealed that another security flaw in Qualcomm (CVE-2024-43047) had been exploited by the Serbian Security Information Agency (BIA) and the Serbian police to unlock seized Android devices belonging to activists, journalists, and protestors using Cellebrite's data extraction software to gain elevated access and deploy an Android spyware called NoviSpy.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2025/06/qualcomm-fixes-3-zero-days-used-in.html